$ cat jobs/cybersecurity-incident-response-engineer-worldwildlifefundinc1-c5af9dd8975c.json
Cybersecurity Incident Response Engineer
Founded in 1961, WWF works to help people and nature thrive. As a global conservation organization, WWF operates in more than 100 countries, partnering with communities, companies, and governments to protect wildlife, conserve vital habitats, and advance sustainable solutions. Grounded in science and driven by collaboration, WWF works to help nature by conserving biodiversity, supporting resilient communities, and addressing climate change. Nearly 1 million people in the United States and more than 5 million globally are WWF members. Major Function The Cybersecurity Incident Response (IR) Engineer at WWF protects the organization’s global mission by designing and operating capabilities to detect, investigate, and respond to cyber threats in WWF US and its Country Offices. The role works closely with security leadership and cross-functional teams to coordinate response efforts and strengthen security posture across WWF’s operations. The engineer leads technical investigations, containment, and remediation of incidents while developing automation, playbooks, and improved detection capabilities. Using data-driven analysis and threat intelligence, the role assesses risk and implements solutions that enhance resilience and reduce exposure. Success requires strong technical expertise, an engineering mindset, and the ability to translate complex security issues into business impact in a mission-driven environment. Key Responsibilities Incident Response Execution: Leads and supports investigation, containment, and remediation of cybersecurity incidents, including ransomware, account compromise, phishing, and data leakage across enterprise environments. Operational Monitoring: Monitors and responds to security events across endpoints, networks, cloud services, applications, databases, and third-party environments. Threat Detection & Analysis: Collects, correlates, and analyzes data from multiple internal and external sources to identify anomalies, validate threats, and suppo